<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:51:16 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:2340 — Moderate: libtiff security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:2340</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libtiff, AlmaLinux:9: libtiff-devel, AlmaLinux:9: libtiff-tools&lt;/p&gt;
&lt;p&gt;The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libtiff: heap Buffer overflows in tiffcrop.c (CVE-2022-3570)
* libtiff: out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix (CVE-2022-3597)
* libtiff: out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c (CVE-2022-3598)
* libtiff: out-of-bounds read in writeSingleSection in tools/tiffcrop.c (CVE-2022-3599)
* libtiff: out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c (CVE-2022-3626)
* libtiff: out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c (CVE-2022-3627)
* libtiff: integer overflow in function TIFFReadRGBATileExt of the file (CVE-2022-3970)
* libtiff: out-of-bounds read in tiffcp in tools/tiffcp.c (CVE-2022-4645)
* libtiff: heap buffer overflow issues related to TIFFTAG_INKNAMES and related TIFFTAG_NUMBEROFINKS value (CVE-2023-30774)
* libtiff: Heap buffer overflow in extractContigSamples32bits, tiffcrop.c (CVE-2023-30775)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libtiff, AlmaLinux:9: libtiff-devel, AlmaLinux:9: libtiff-tools&lt;/p&gt;
&lt;p&gt;The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libtiff: heap Buffer overflows in tiffcrop.c (CVE-2022-3570)
* libtiff: out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix (CVE-2022-3597)
* libtiff: out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c (CVE-2022-3598)
* libtiff: out-of-bounds read in writeSingleSection in tools/tiffcrop.c (CVE-2022-3599)
* libtiff: out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c (CVE-2022-3626)
* libtiff: out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c (CVE-2022-3627)
* libtiff: integer overflow in function TIFFReadRGBATileExt of the file (CVE-2022-3970)
* libtiff: out-of-bounds read in tiffcp in tools/tiffcp.c (CVE-2022-4645)
* libtiff: heap buffer overflow issues related to TIFFTAG_INKNAMES and related TIFFTAG_NUMBEROFINKS value (CVE-2023-30774)
* libtiff: Heap buffer overflow in extractContigSamples32bits, tiffcrop.c (CVE-2023-30775)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:2340</guid>
    </item>
    <item>
      <title>bdu:2022-06974</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06974</link>
      <description>bdu:2022-06974</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06974</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-3970 — CVE-2022-3970 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-3970</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-3970</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0218 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218</link>
      <description>certfr-2026-avi-0218</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0218</guid>
    </item>
    <item>
      <title>EUVD-2026-229488</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-229488</link>
      <description>EUVD-2026-229488</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-229488</guid>
    </item>
    <item>
      <title>fkie_cve-2022-3970</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-3970</link>
      <description>&lt;p&gt;A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-3970</guid>
    </item>
    <item>
      <title>GHSA-44v9-23w3-fv66</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-44v9-23w3-fv66</link>
      <description>&lt;p&gt;A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-44v9-23w3-fv66</guid>
    </item>
    <item>
      <title>gsd-2022-3970</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-3970</link>
      <description>gsd-2022-3970</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-3970</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-3970 — LibTIFF tif_getimage.c TIFFReadRGBATileExt integer overflow</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-3970</link>
      <description>msrc_CVE-2022-3970</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-3970</guid>
    </item>
    <item>
      <title>OESA-2022-2108 — libtiff security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-2108</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libtiff, openEuler:20.03-LTS-SP3: libtiff, openEuler:22.03-LTS: libtiff&lt;/p&gt;
&lt;p&gt;This package contains the header files and documentation necessary for developing programs which will manipulate TIFF format image files using the libtiff library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.(CVE-2022-3970)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libtiff, openEuler:20.03-LTS-SP3: libtiff, openEuler:22.03-LTS: libtiff&lt;/p&gt;
&lt;p&gt;This package contains the header files and documentation necessary for developing programs which will manipulate TIFF format image files using the libtiff library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.(CVE-2022-3970)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-2108</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12510-1 — libtiff-devel-32bit-4.4.0-5.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12510-1</link>
      <description>&lt;p&gt;libtiff-devel-32bit-4.4.0-5.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libtiff-devel-32bit-4.4.0-5.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12510-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:4248-1 — Security update for tiff</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:4248-1</link>
      <description>&lt;p&gt;Security update for tiff&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tiff&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:4248-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-3970</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-3970</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: tiff, Ubuntu:18.04:LTS: tiff, Ubuntu:20.04:LTS: tiff, Ubuntu:22.04:LTS: tiff&lt;/p&gt;
&lt;p&gt;A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tiff, Ubuntu:Pro:16.04:LTS: tiff, Ubuntu:18.04:LTS: tiff, Ubuntu:20.04:LTS: tiff, Ubuntu:22.04:LTS: tiff&lt;/p&gt;
&lt;p&gt;A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-3970</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2035 — libTIFF: Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2035</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libTIFF ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libTIFF ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2035</guid>
    </item>
  </channel>
</rss>
